← Back

CVE-2024-50007

nvd nist
Published: Oct 21, 2024Modified: Nov 3, 2025

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: asihpi: Fix potential OOB array access ASIHPI driver stores some values in the static array upon a response from the driver, and its index depends on the firmware. We shouldn't trust it blindly. This patch adds a sanity check of the array index to fit in the array size.

Affected (6)

Products: Linux: Linux Kernel
1 product
Linux Kernel
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Linux
Before 5.10.227
From 5.11 to 5.15.168
From 5.16 to 6.1.113
From 6.11 to 6.11.3
From 6.2 to 6.6.55
From 6.7 to 6.10.14

References (11)

Timeline

No history available yet.